Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Trac Trac
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Service Desk
    • Milestones
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
  • Wiki
    • Wiki
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar
  • Legacy
  • TracTrac
  • Issues
  • #27226

Closed (moved)
(moved)
Open
Created Aug 20, 2018 by Nick Mathewson@nickm🍬

Crash in tortls/cert_matches_key with openssl 1.0.2p

Our unit test, tortls/cert_matches_key, does some questionable stuff that is not compatible with openssl 1.0.2p.

Namely, it calls EVP_PKEY_asn1_new(999, 0, NULL, NULL), which now returns NULL.

Looking at the test, I'm not sure what it's trying to do with this -- it's making a bogus public key method with a "compare" function that will always return "1". Later, it's using this thing to construct bogus PKEY objects.

This, like a lot of other tortls.c tests, is way too tightly coupled to openssl internals.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking